New
- agents: prefer local review and focused validation (#111) (e7f5f7b3ed0d)
- ui: explain diagnostic result details (#109) (9d9957c478f2)
Fixed
- ui: align OIDC form controls with active theme (#106) (254f6d66d3e5)
Documentation
- add reproducible plugin screenshots (#107) (df0cc24443dd)
Tests
- e2e: add tiered provider validation (#104) (5aba7d6b6236)
Housekeeping
- follow OPNsense licensing conventions (#105) (8eded1a43b58)
Verify and install
pkg checks nothing about a file handed to it directly. Establish its
GitHub/Sigstore provenance before the package reaches the firewall.
On an administrator workstation:
curl --fail --location --output /tmp/os-openid-connect-1.0.0.beta5.pkg \
https://github.com/jpawlowski/opnsense-openid-connect/releases/download/v1.0.0-beta5/os-openid-connect-1.0.0.beta5.pkg
gh attestation verify /tmp/os-openid-connect-1.0.0.beta5.pkg \
-R jpawlowski/opnsense-openid-connect \
--signer-workflow jpawlowski/opnsense-openid-connect/.github/workflows/build.yml \
--deny-self-hosted-runners
Copy that verified package to /tmp on the firewall. Confirm that the
transfer preserved its exact bytes, then install it:
sha256 -c 4b222b0de4ff9523cf3c86b23e984507e21c9a92a02bafe7cc01e406a41b117c /tmp/os-openid-connect-1.0.0.beta5.pkg
pkg add /tmp/os-openid-connect-1.0.0.beta5.pkg
No restart, no service affected. Signing in locally with a username and
password is untouched; the way back is always
pkg delete os-openid-connect.
6 commit(s) since v1.0.0-beta4.
Built from e7f5f7b3ed0dc6d71463bd7cbc08d65cbc794e12.